LibreOffice malicious spreadsheet code execution security flaw (CVE-2026-63277)
Vulnerability
Summary
Hide ▲
Show ▼
LibreOffice fixed CVE-2026-63277, a flaw that lets a malicious spreadsheet trigger code execution when opened with Java support enabled. The affected scope covers versions before 26.2.5 or 26.8.0, and the vendor has already released updates. A published proof of concept shows the weakness can execute attacker-controlled Java code without the normal macro warning.
Timeline
-
06.10.2026 14:57 2 articles · 2h ago
LibreOffice releases fixes for CVE-2026-63277
Mitigation Patch UpdateLibreOffice released updates on October 5, 2026 that fixed CVE-2026-63277, a malicious spreadsheet code execution flaw affecting versions before 26.2.5 and 26.8.0; users are advised to upgrade to a fixed version and disable Java if they do not need it.
Show sources
- LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings — thehackernews.com — 06.10.2026 14:57
- LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings — thehackernews.com — 06.10.2026 14:57
-
06.10.2026 14:57 1 articles · 2h ago
Researchers disclose a spreadsheet-driven code execution path in LibreOffice
Initial DisclosureRick de Jager of the V12 security team and Thomas Rinsma and Edoardo Geraci of Codean Labs independently reported CVE-2026-63277, and the V12 team published a proof of concept showing that a Calc spreadsheet can load a database range, download an ODB from a web address, and start a JDBC driver as attacker-controlled Java code when Java support is enabled, bypassing the normal macro trust warning; the proof of concept was tested on Windows and Linux and no real-world abuse has been reported.
Show sources
- LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings — thehackernews.com — 06.10.2026 14:57